[CLSA-2026:1774028255] freerdp: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2026-03-23 14:38:28 UTC
Description:
- CVE-2026-31897: add early length check in planar_decompress to avoid OOB read - CVE-2026-31885: fix array bounds checks in DSP IMA/MS ADPCM codec - CVE-2026-31883: add missing length/bounds checks in DSP ADPCM decoder
Updated packages:
  • freerdp-2.1.1-5.el7_9.tuxcare.els16.x86_64.rpm
    sha:92d797e20b5a4b4805cd05e8ab4d44b041ce98310c9c8ba3c113613a57bc7d0f
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els16.i686.rpm
    sha:d7a116ed24c4af1706dbb97f1a3894af05070af8afaea727cf2fb892211b8b16
  • freerdp-devel-2.1.1-5.el7_9.tuxcare.els16.x86_64.rpm
    sha:15fdad787f1b318901e0e11ea1fc59c1b5bd719cd1a04b2010fcde32e40629cd
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els16.i686.rpm
    sha:9b42d9caa38a740aa1c84e6e59c7da7ee6b5c6cfa7d61aef0fdb8e2149fd3e6b
  • freerdp-libs-2.1.1-5.el7_9.tuxcare.els16.x86_64.rpm
    sha:5819e9d1f69ef0d0c1feea199003f91803187ff0a934aba1ccc047bcd20f960c
  • libwinpr-2.1.1-5.el7_9.tuxcare.els16.i686.rpm
    sha:c00aecd2bc8eacbdff20d524e74e57d1e224f3e8fd5f55b376b46ca92df6e245
  • libwinpr-2.1.1-5.el7_9.tuxcare.els16.x86_64.rpm
    sha:71870662c2404124d10d69656e573a31951e46deedf0f1207b2c22be76aab61d
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els16.i686.rpm
    sha:f6ea31bb0357f6246a217e6ecf7ff09bb4272de72ed017215dab3556f19d50ab
  • libwinpr-devel-2.1.1-5.el7_9.tuxcare.els16.x86_64.rpm
    sha:a689c4272b35b2b8fee0bfff562d16af026a6ffa5b2f516a3665c4491b6294e3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.